← Back to plugin index

Default Password Reset Restrictions

Description

Default restrictions for password reset flows. Currently, they are (in this order):

  • Nonexistent User Restriction
  • Invalid User Restriction
  • Locked User Restriction

By default, these restrictions do not report violations and therefore prevent user enumeration. To include custom restrictions or to configure restrictions for other types of self-service flows, the "Custom Public Self-Service Restrictions" plugin can be used.

Type name
DefaultPasswordResetRestrictions
Class
com.airlock.iam.publicselfservice.application.configuration.restrictions.DefaultPasswordResetRestrictionsConfig
May be used by
Properties
Allow Locked User (allowLockedUser)
Description

If enabled, users that are locked because of too many failed password checks (lock reason "LockReason.TooManyAuthAtts.PASSWORD") are allowed to perform a password reset flow. Locked users with any other lock reason cannot reset their password. To allow other lock reasons, use the "Locked User Restriction" plugin with "Custom Public Self-Service Restrictions".

Attributes
Boolean
Optional
Default value
false
Nonexistent User Feedback (nonexistentUserFeedback)
Description

If enabled, nonexistent users attempting to start a password reset flow receive an error response with error code "USER_NOT_FOUND". Otherwise, the flow would also continue for nonexistent users but fail in the verification step (to protect against user enumeration).

Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.

Attributes
Boolean
Optional
Default value
false
Invalid User Feedback (invalidUserFeedback)
Description

If enabled, invalid users attempting to start a password reset flow receive an error response with error code "USER_INVALID". Otherwise, the flow would also continue for invalid users, but fail in the verification step (to protect against user enumeration).

Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.

Attributes
Boolean
Optional
Default value
false
Locked User Feedback (lockedUserFeedback)
Description

If enabled, locked users attempting to start a password reset flow receive an error response with error code "USER_LOCKED". Otherwise, the flow would also continue for locked users but fail in the verification step (to protect against user enumeration).

Security consideration: Enabling feedback on restriction violations can increase usability but it weakens or disables the user enumeration protection.

Attributes
Boolean
Optional
Default value
false
YAML Template (with default values)

type: DefaultPasswordResetRestrictions
id: DefaultPasswordResetRestrictions-xxxxxx
displayName: 
comment: 
properties:
  allowLockedUser: false
  invalidUserFeedback: false
  lockedUserFeedback: false
  nonexistentUserFeedback: false